Privacy policy
Last updated ·
Draft prepared with AI assistance; the operator should have it reviewed by a qualified lawyer.
This policy explains, in plain language, what the MedCourseFinder website actually stores about you today, why, and what rights you have. It describes the current behaviour of the software; if it changes, this page is updated first.
In short
You can read all reference pages without an account. We use no advertising, no analytics and no third-party tracking scripts at present. The only personal data we hold server-side is what you give us if you create an account or send a report. Your study progress and preferences stay in your own browser.
Who is responsible
The data controller is the publisher of the site, identified in the legal notice (name, address and contact details). Questions about this policy or your data should be sent to the contact address below.
- Contact email
- To be completed by the operator
See also: Legal notice
Data we collect
Depending on what you do, the following data is processed:
- Account (optional): your email address, a password hash (the password is never stored; it is hashed with scrypt with a random salt), your preferred language, and technical session records (a hash of the session token and its expiry). Staff accounts may also hold a two-factor secret.
- Session cookie: if you sign in, a cookie holds a random session token. Only a hash of that token is stored on our server.
- Error reports: if you use “Report incorrect information”, we store the text you write, the optional suggested correction and optional source link, the page and section concerned, the category and your language. At present a report is not linked to your account and no IP address is stored with it. Please do not include personal or patient information in a report.
- IP address: used briefly to limit abusive use (rate limiting) of sign-in, registration, reports, the document assistant, drug search and Anki import and export. For sign-in attempts the email address you typed is also used in a short-lived counter. These counters live in memory or in a cache with an automatic expiry and are not attached to a profile.
- Server and security logs: our hosting setup may record standard request data (IP address, date, requested address, browser type) for security and troubleshooting.
- Document assistant (optional): PDF files are read in your browser and are not uploaded. When you ask a question, the question and short text excerpts from your document are sent to our server to produce an answer. The app does not store them.
- Drug search: the name you type is sent to our server, which queries the public openFDA service on your behalf. Your browser does not contact openFDA directly.
- Language cookie: see the cookies page.
- In your browser only: theme, navigation layout, flashcard, practice-question and study-planner data, saved in local storage and never sent to us.
Why we use it, and the legal basis
To provide the account and keep you signed in: performance of the service you asked for. To receive and review error reports and improve the accuracy of the content: our legitimate interest in the quality of an educational resource. To prevent abuse and keep the service secure: our legitimate interest. Where the law requires consent, we ask for it. We do not sell personal data, do not profile you and do not take automated decisions about you.
Cookies and local storage
MedCourseFinder uses only strictly necessary or user-requested storage, listed one by one with its duration on the cookies page. Because of this, no consent banner is shown.
See also: Cookies and local storage
How long we keep data
Session cookies and records are valid for 14 days (8 hours for staff accounts) or until you sign out. Account data is kept until you ask us to delete the account. Error reports are kept as long as they are needed to review them and to keep a history of corrections; no automatic deletion period is currently implemented, and we delete a report on request when it can be identified. Rate-limiting counters expire automatically after their window (minutes to one hour). Server logs are kept for the short period set in the hosting configuration. Data in your browser stays until you clear it.
Who receives data
Your data is accessible to the operator and to the limited staff who maintain the service. We use the following technical providers, who act only as infrastructure and do not use your data for their own purposes: the hosting provider named in the legal notice (servers and network), and the certificate authority that issues the website’s TLS certificate (it does not receive your data). If the operator has enabled an external AI provider for the document assistant, your question and the document excerpts are sent to that provider to generate the answer; otherwise a built-in extractive method is used and nothing is sent. The drug search queries the US openFDA service from our server. We do not share data with advertisers or data brokers.
International transfers
The country in which the servers are located is stated in the legal notice. If your data is processed outside your country of residence, for example by the hosting provider or by an optional external AI provider, we rely on the safeguards available under applicable law (such as standard contractual clauses or an adequacy decision) where required. No other transfer is made.
See also: Legal notice
Your rights
Under the General Data Protection Regulation (GDPR), where it applies, and under Moroccan Law 09-08 on the protection of individuals with regard to the processing of personal data, you have the right to:
- access the data we hold about you;
- have inaccurate data corrected (rectification);
- have your data erased (the right to be forgotten);
- receive your data in a structured, commonly used format (portability);
- object to, or ask us to restrict, certain processing;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a supervisory authority: your national data-protection authority or, in Morocco, the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).
How to exercise your rights
Write to the contact address below from the email address of your account, stating what you want. We may ask you to confirm your identity. We aim to reply within one month. To delete your account yourself from the browser, you can clear the cookie and local data (see the cookies page); to delete the server-side account, send us a request.
- Contact email
- To be completed by the operator
Children
MedCourseFinder is aimed at students and professionals and is not designed for children. We do not knowingly collect data from children under 16 (or the age set by local law). If you believe a child has created an account, contact us and we will delete it.
Security
Passwords are hashed with scrypt and never stored in clear text. Session tokens are random and only their hash is stored. The session cookie is HttpOnly, Secure and SameSite=Lax, and uses the __Host- prefix. The site is served over HTTPS with HTTP Strict Transport Security and a strict Content-Security-Policy; forms and requests are checked to come from the site itself. Sign-in, registration, reports and other endpoints are rate limited, and privileged accounts require a second factor. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.
Changes to this policy
We update this page when the software or our practices change, and show the new date at the top. Material changes are highlighted on the page before they take effect.